Runtime Monitoring: From Theory to Usable Security
Runtime Monitoring: From Theory to Usable Security
批准号:
RGPIN-2015-04142
负责人:
Khoury, Raphaël
金额:
$1.31万
依托单位国家:
加拿大
项目类别:
Discovery Grants Program - Individual
财政年份:
2016
资助国家:
加拿大
项目状态:
已结题
起止时间:
2016-01-01 至 2017-12-31
中文摘要
根据2013年诺顿报告,仅在2013年,网络犯罪就给加拿大造成了超过30亿美元的损失。在全球范围内,成本估计达到1130亿美元。因此,政府和工业界都对开发保护敏感系统和数据的工具产生了浓厚的兴趣。运行时监视是一种执行安全策略的方法,它通过观察不受信任的代码的执行并根据需要作出反应来防止违反用户提供的安全策略,从而寻求允许不受信任的代码安全运行。这种确保代码安全的方法在实践中迅速得到认可,并且存在几种实现。这种扩散引起了学术界的兴趣,科学文献中提出了许多有趣和创新的想法,使监视器成为一种有吸引力和强大的安全策略执行选项。这类想法的一些示例包括内存使用开销为零的监视器、监视器认证(一种为监视器的正确实施提供用户可检查证明的技术)和信息流监控(与隐私相关的一类特定策略)。
英文摘要
According to the 2013 Norton Report, cyber-crime has cost Canadian upwards of 3 Bilion US$ in 2013 alone. Globally, the costs are estimated to reach 113 Billion US$. As a consequence, both government and industry have taken a keen interest in developing tools to protect sensitive systems and data. Runtime monitoring is an approach to enforcing security policies that seeks to allow untrusted code to run safely by observing its execution and reacting as needed to prevent a violation of a user-supplied security policy. This method of ensuring the safety of code is rapidly gaining acceptance in practice and several implementations exist. This proliferation has prompted interest from the academic community, and many interesting and innovative ideas have been proposed in the scientific literature to make monitors an attractive and powerful security policy enforcement option. A few examples of such ideas include monitors with zero overhead in memory usage, monitor certification—a technique to provide a user-checkable proof of the monitor’s correct enforcement, and the monitoring of information flow, a particular class of policies that relates to privacy.
However, practical implementations of monitors do not draw upon the vast body of scholarly research that relates to monitoring. Indeed, most remain limited to the enforcement of a narrow subset of security policies and rely upon only one of the multiple mechanisms at their disposal to avert a potential violation of the security policy, namely aborting the execution. Conversely, theoretical research in monitoring abstracts away many aspects of a real-life monitor that would make implementation more laborious. For example, research-paper monitors are often tested on short execution traces of a few hundred events and do not scale up to the many millions of events of real execution traces.
This research program seeks to bridge the divide between theoretical research and practical implementations of monitors. On the one hand, we will develop software that exploit the full potential of monitors highlighted in the scientific literature and issue them as ready-to-use security tools. We are particularly interested in developing a usable monitor certification framework, and diversity-based HIDS. On the other hand, our work will also push theoretical research forward through our study of the pitfalls encountered when implementing monitors and provide the scientific community with real tools and test data to use in monitor research.
The upshot of this research will be the development of monitors that are more powerful, in the sense that can enforce a larger set of security policies, more precise, meaning that they can detect violations with less risk of a false positive, and with a lower footprint of resource consumption. This research will also allow us to refine the theoretical models used to reason about the capacities of monitors.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Ensuring User control of Personal Information Though the Blockchain
-
批准号:DDG-2020-00033
-
项目类别:Discovery Development Grant
-
资助金额:$1.09万
-
财政年份:2021
-
负责人:Khoury, Raphaël
-
依托单位:
Ensuring User control of Personal Information Though the Blockchain
-
批准号:DDG-2020-00033
-
项目类别:Discovery Development Grant
-
资助金额:$1.09万
-
财政年份:2020
-
负责人:Khoury, Raphaël
-
依托单位:
Runtime Monitoring: From Theory to Usable Security
-
批准号:RGPIN-2015-04142
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.31万
-
财政年份:2019
-
负责人:Khoury, Raphaël
-
依托单位:
Runtime Monitoring: From Theory to Usable Security
-
批准号:RGPIN-2015-04142
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.31万
-
财政年份:2018
-
负责人:Khoury, Raphaël
-
依托单位:
Runtime Monitoring: From Theory to Usable Security
-
批准号:RGPIN-2015-04142
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.31万
-
财政年份:2017
-
负责人:Khoury, Raphaël
-
依托单位:
Runtime Monitoring: From Theory to Usable Security
-
批准号:RGPIN-2015-04142
-
项目类别:Discovery Grants Program - Individual
-
资助金额:$1.31万
-
财政年份:2015
-
负责人:Khoury, Raphaël
-
依托单位:
海外基金